TechTV's Leo Laporte and I spend somewhat shy of two hours each week to discuss important issues of personal computer security. Sometimes we'll discuss something that just happened. Sometimes we'll talk about long-standing problems, concerns, or solutions. Either way, every week we endeavor to produce something interesting and important for every personal computer user.

(This was not our idea. It was created by a fan of the podcast using GIMP (similar toPhotoshop). But as a work of extreme image manipulation, it came out surprisingly well.)

Receive an automatic eMail reminder whenever a new episode is posted here (from ChangeDetection.com). See the section at the bottom of this page.Send us your feedback: Use the form at the bottom of the page to share your opinions, thoughts, ideas, and suggestions for future episodes.Leo also produces "This Week in Tech" (TWiT) and a number of other very popular podcasts (TWiT is America's most listened to podcast!) So if you are looking for more informed technology talk, be sure to check out Leo's other podcasts and mp3 files.And a huge thanks to AOL Radio for hosting the high-quality MP3 files and providing the bandwidth to make this series possible. We use "local links" to count downloads, but all of the high-quality full-size MP3 files are being served by AOL Radio.

(Note that the text transcripts will appear a few hours laterthan the audio files since they are created afterwards.)

For best results: RIGHT-CLICK on one of the two audio icons & below then choose "Save Target As..." to download the audio file to your computer before starting to listen. For the other resources you can either LEFT-CLICK to open in your browser or RIGHT-CLICK to save the resource to your computer.

Episode #650 | 13 Feb 2018 | 90 min.

Cryptocurrency AnticsThis week we discuss today’s preempted Second Tuesday of the Month, slow progress on the Intel Spectre firmware update front, a worse-than-originally-thought Cisco firewall appliance vulnerability, the unsuspected threat of hovering hacking drones, hacking at the Winter Olympics, Kaspersky’s continuing unhappiness, the historic leak of Apple’s iOS boot source code, a critical WiFi update for some Lenovo laptop users, a glitch at WordPress, a bit of miscellany (including a passwords rap), some closing-the-loop feedback from our listeners, and then a look at a handful of cryptocurrency antics.

42 MB

11 MB

218 KB

96 KB

67 KB

126 KB

Episode #649 | 06 Feb 2018 | 88 min.

Meltdown & Spectre EmergeThis week we observe that the Net Neutrality battle is actually FAR from lost. Computerworld's Woody Leonard enumerates a crazy January of updates. EternalBlue is turning out to be far more "eternal" than we'd wish. Will Flash EVER die? There's a new zero-day Flash exploit in the wild. What happens when you combine Shodan with Metasploit? Firefox 59 takes another privacy-enhancing step forward. We've got a questionable means of sneaking data between systems; another fun SpinRite report from the field; some closing-the-loop feedback from our listeners; and, finally, a look at the early emergence of Meltdown and Spectre exploits appearing in the wild.

42 MB

11 MB

184 KB

101 KB

65 KB

124 KB

Episode #648 | 30 Jan 2018 | 107 min.

Post Spectre?This week we discuss continuing Spectre updates, how not to treat Tavis Ormandy, a popular dating app where you'd really hope for HTTPS but be surprised to find it missing, the unintended consequences of global posting of fitness tracking data, gearing up (or not) for this year's voting machine hack'fest, another record broken by a cryptocurrency exchange heist, bad ads and fake ads, the unclear fate of the BSD operating systems, a caution about Dark Caracal's CrossRAT Trojan, another way to skin the Net Neutrality cat, a bit of errata and miscellany, one of the best SpinRite testimonials in a long time, and some closing the loop feedback from our terrific listeners.

50 MB

13 MB

140 KB

114 KB

79 KB

145 KB

Episode #647 | 23 Jan 2018 | 105 min.

The Dark CaracalThis week's news continues to be dominated by the industry-shaking Meltdown and Spectre vulnerabilities. We will catch up with what's new there, then discuss the Net Neutrality violation detection apps that are starting to appear; a new app and browser plugin from the search privacy provider DuckDuckGo; a bit of welcome news from Apple's Tim Cook about their planned response to the iPhone battery-life and performance debacle; a bit of errata; and some feedback from our terrific listeners. Then we take a look into a state-level, state-sponsored, worldwide, decade-long cyberespionage campaign which the EFF and Lookout Security have dubbed “Dark Caracal.”

50 MB

13 MB

309 KB

129 KB

78 KB

145 KB

Episode #646 | 16 Jan 2018 | 91 min.

The InSpectreThis week we discuss more trouble with Intel’s AMT, what Skype’s use of Signal really means, the UK’s data protection legislation giving researchers a bit of relief, the continuing winding down of HTTP, “progress” on the development of Meltdown attacks, Google successfully tackling the hardest to fix Spectre concern with a Return Trampoline, some closing-the-loop feedback with our terrific listeners, and the evolving landscape of Meltdown and Spectre – including Steve’s just completed “InSpectre” test and explanation utility.

44 MB

11 MB

140 KB

126 KB

71 KB

138 KB

Episode #645 | 09 Jan 2018 | 116 min.

The Speculation MeltdownThis week, before we focus upon the industry-wide catastrophe enabled by precisely timing the instruction execution of all contemporary high-performance processor architectures, we examine a change in Microsoft’s policy regarding non-Microsoft AV systems, Firefox Quantum’s performance when tracking protections are enabled, the very worrisome hard-coded backdoors in 10 of Western Digital’s My Cloud drives; and, if at first (WEP) and at second (WPA) and at third (WPA2) and at fourth (WPS) you don’t succeed, try, try, try, try, try yet again with WPA3, another crucial cryptographic system being developed by a closed members-only committee.

55 MB

14 MB

222 KB

116 KB

84 KB

162 KB

Episode #644 | 02 Jan 2018 | 118 min.

NSA Fingerprints
This week we discuss a new clever and disheartening abuse of our browsers’ handy-dandy username and password autofill, some recent and frantic scurrying around by many OS kernel developers, a just-released MacOS zero-day allowing full local system compromise, another massively popular router falls to the IoT botnets, even high-quality IoT devices have problems, the evolution of adblocking and countermeasures, an important update for Mozilla’s Thunderbird, a bit of miscellany, listener feedback, and an update on the NSA’s possible intervention into secure encryption standards.

56 MB

14 MB

172 KB

132 KB

86 KB

155 KB

Episode #642 | 19 Dec 2017 | 120 min.

BGPThis week we examine how Estonia handled the Infineon crypto bug; two additional consequences of the pressure to maliciously mine cryptocurrency; zero-day exploits in the popular vBulletin forum system; Mozilla in the doghouse over “Mr. Robot”; Win10’s insecure password manager mistake; when legacy protocol come back to bite us; how to bulk-steal any Chrome user’s entire stored password vault; and we finally know where and why the uber-potent Mirai botnet was created, and by whom. We also have a bit of errata and some fun miscellany. Then we’re going to take a look at BGP, another creaky yet crucial – and vulnerable – protocol that glues the global Internet together.

58 MB

14 MB

186 KB

124 KB

85 KB

154 KB

Episode #641 | 12 Dec 2017 | 125 min.

The iOS 11 Security TradeoffThis week we discuss the details behind the “USB/JTAG takeover” of Intel’s Management Engine, a rare Project Zero discovery, Microsoft’s well-meaning but ill-tested IoT security project, troubles with EV certs, various cryptocurrency woes, a clever DNS spoofing detection system, a terrific guide to setting up the EdgeRouter X for network segmentation, last week’s emergency out-of-cycle patch from Microsoft, a mitigated vulnerability in Apple’s HomeKit, Valve’s ending of Bitcoin for Steam purchases, finally some REALLY GOOD news in the elusive quest for encrypted email, a bit of miscellany, some closing-the-loop feedback with our listeners, and a look at the security sacrifice Apple made in the name of convenience and what it means.

59 MB

15 MB

196 KB

134 KB

93 KB

166 KB

Episode #640 | 05 Dec 2017 | 104 min.

More News & FeedbackThis week we discuss the long-awaited end of StartCom & StartSSL, inside last week’s macOS passwordless root account access and problems with Apple’s patches, the question of Apple allowing 3D facial data access to apps, Facebook’s new and controversial use of camera images, in-the-wild exploitation of one of last month’s patched Windows vulnerabilities, an annoying evolution in browser-based cryptocurrency mining, exploitation of Unicode in email headers, Google’s advancing protection for Android users, a terrific list of authentication dongle-supporting sites and services, Mirai finds another 100,000 exposed ZyXEL routers, Google moves to reduce system crashes, a bit of miscellany including another security-related Humble Bundle offering, and some closing-the-loop feedback from our terrific listeners.

50 MB

12 MB

304 KB

129 KB

78 KB

147 KB

Episode #639 | 28 Nov 2017 | 129 min.

News & FeedbackThis week we discuss a new bad bug found in the majority of SMTP mailing agents, 54 high-end HP printers found to be remotely exploitable, more than 3/4ths of 433,000 websites are using vulnerable JavaScript libraries, horrible free security software, some additional welcome Firefox news, a bit of errata, some fun miscellany, and a BUNCH of feedback from our listeners including reactions to last week's Quad 9 recommendation.

62 MB

15 MB

459 KB

134 KB

102 KB

178 KB

Episode #638 | 21 Nov 2017 | 93 min.

Quad NineThis week we discuss Windows having a birthday, Net Neutrality about to succumb to big business despite a valiant battle, Intel's response to the horrifying JTAG over USB discovery, another surprising AWS public bucket discovery, Android phones caught sending position data when all permissions are denied, many websites found to be watching their visitors' actions, more Infineon ID card upset, the return of BlueBorne, a new arrival to our "Well, THAT didn't take long" department, speedy news for Firefox 57, some miscellany, listener feedback, and a look at the very appealing and speedy new "Quad 9" alternative DNS service.

44 MB

11 MB

360 KB

107 KB

70 KB

130 KB

Episode #637 | 14 Nov 2017 | 131 min.

Schneier on EquifaxThis week we discuss why Steve won’t be relying upon Face ID for security, a clever new hack of longstanding NTFS and Windows behavior, the Vault 8 WikiLeaks news, the predictable resurgence of the consumer device encryption battle, a new and clever data exfiltration technique, new antimalware features coming to Chrome, an unbelievable discovery about access to the IME in Skylake and subsequent Intel chipsets, a look at who’s doing the unauthorized crypto mining, WebAssembly is ready for primetime, a bit of miscellany, some closing-the-loop feedback with our listeners – and then we share Bruce Schneier’s congressional testimony about the Equifax breach.

62 MB

16 MB

389 KB

144 KB

97 KB

174 KB

Episode #636 | 07 Nov 2017 | 97 min.

ROCA PainThis week we discuss the inevitable dilution in the value of code signing, a new worrisome cross-site privacy leakage, is Unix embedded in all our motherboards?, the ongoing application spoofing problem, a critical IP address leakage vulnerability in TOR and the pending major v3 upgrade to TOR, a Signal app for ALL our desktops, an embarrassing and revealing glitch in Google Docs, bad behavior by an audio driver installer, a pending RFC for IoT updating, two reactions to Win10 Controlled Folder Access, a bit of miscellany, some closing the loop with our listeners, and, three weeks after the initial ROCA disclosure I'm reminded of two lines from the movie "Serenity" -- Assassin:"It's worse than you know." Mal:"It usually is."

46 MB

12 MB

294 KB

126 KB

75 KB

140 KB

Episode #635 | 31 Oct 2017 | 127 min.

Reaper ReduxThis week we examine the source of WannaCry, a new privacy feature for Firefox, Google's planned removal of HPKP, the idea of visual objects as a second factor, an iOS camera privacy concern, the CAPTCHA wars, a horrifying glimpse into a non-Net Neutrality world, the Coinhive DNS hijack, the new Bad Rabbit cryptomalware, a Win10 anti-cryptomalware security tip, spying vacuum cleaners, a new Amazon service, some loopback Q&A with our listeners, and another look at the Reaper botnet.

61 MB

15 MB

477 KB

148 KB

95 KB

172 KB

Episode #634 | 24 Oct 2017 | 123 min.

IoT Flash BotnetsThis week we discuss some ROCA fallout specifics, an example of PRNG misuse, the Kaspersky Lab controversy, a DNS security initiative for Android, another compromised download occurrence, a browser-based cryptocurrency miner for us to play with... and Google considering blocking them natively, other new protections coming to Chrome, an update on Marcus Hutchins, Microsoft's "TruePlay" being added to the Win10 fall creators update, some interesting "Loopback" from our terrific listeners... and then we take a closer look at the rapidly growing threat of IoT-based "Flash Botnets."

59 MB

15 MB

317 KB

147 KB

92 KB

168 KB

Episode #633 | 17 Oct 2017 | 120 min.

KRACKing WiFiThis week we examine ROCA's easily factorable public keys, the surprising prevalence of web-based cryptocurrency mining, some interesting work in iOS dialog password dialog spoofing, Google's Advanced Protection Program, some good "Loopback" comments from our listeners... and then we take a close look at KRACK - the Key Reinstallation AttaCK against ALL unpatched WiFi systems.

57 MB

14 MB

577 KB

166 KB

93 KB

171 KB

Episode #632 | 10 Oct 2017 | 109 min.

The DNSSEC ChallengeThis week we take a look at a well-handled breach-response at Discus, a rather horrifying mistake Apple made in the implementation of their APFS encryption (and the difficulty to the user of fully cleaning up after it), the famous "robots.txt" file gets a brilliant new companion, somewhat shocking news about Windows XP... or is it?, Firefox EOL for Windows XP support coming next summer, the sage security thought for the day, an update on "The Orville", some closing the loop comments, including a recommendation of the best Security Now series we did in the past... and finally, a look at the challenge of DNSSEC.

52 MB

13 MB

340 KB

129 KB

81 KB

151 KB

Episode #631 | 03 Oct 2017 | 120 min.

Private Contact DiscoveryThis week we discuss some aspects of iOS v11, the emergence of browser hijack cryptocurrency mining, new information about the Equifax hack, Google security research and Gmail improvements, breaking DKIM without breaking it, concerns over many servers in small routers and aging unpatched motherboard EFI firmware, a new privacy leakage bug in IE, a bit of miscellany, some long-awaited closing-the-loop feedback from our listeners, and a close look into a beautiful piece of work by Moxie & Co. on Signal.

59 MB

14 MB

269 KB

135 KB

89 KB

161 KB

Episode #630 | 25 Sep 2017 | ??? min.

The Great DOM Fuzz-OffThis week, Father Robert and I follow more Equifax breach fallout, look at encryption standards blowback from the Edward Snowden revelations, examine more worrisome news of the CCleaner breach, see that ISPs may be deliberately infecting their own customers, warn that turning off iOS radios doesn't, look at the first news of the FTC's suit against D-Link's poor security, examine a forthcoming Broadcom GPS chip features, warn of the hidden dangers of high-density barcodes, discuss Adobe's disclosure of their own private key, close the loop with our listeners, and examine the results of DOM fuzzing at Google's Project Zero.

57 MB

14 MB

267 KB

123 KB

98 KB

169 KB

Episode #629 | 19 Sep 2017 | 120 min.

Apple Bakes CookiesThis week Padre and I discuss what was up with SN's recent audio troubles, more on the Equifax fiasco, the EFF and Cory Doctorow weigh in on forthcoming browser-encrypted media extensions (EME), an emerging browser-based payment standard, when two-factor is not two-factor, the CCleaner breach and what it means, a new Bluetooth-based attack, an incredibly welcome and brilliant cookie privacy feature in iOS 11, and a heads-up caution about the volatility of Google's Android smartphone cloud backups.

57 MB

14 MB

249 KB

126 KB

101 KB

172 KB

Episode #628 | 12 Sep 2017 | 108 min.

The Equifax FiascoThis week we discuss last Friday's passing of our dear friend and colleague Jerry Pournelle, when AI is turned to evil purpose, whether and when Google's Chrome browser will warn of man in the middle attacks, why Google is apparently attempting to patent pieces of a compression technology they did not invent, another horrifying router vulnerability disclosure -- including ten 0-day vulnerabilities, an update on the sunsetting of Symantec's CA business unit, another worrying failure at Comodo, a few quick bits, an update on my one commercial product SpinRite, answering a closing the loop question from a listener, and a look at the Equifax fiasco.

52 MB

13 MB

326 KB

114 KB

83 KB

148 KB

Episode #627 | 05 Sep 2017 | 119 min.

SharknadoAlthough there are an unbelievable FIVE “Sharknado” movies, this will be the first and last time we use that title for a podcast! This week we have another update on Marcus Hutchins. We discuss the validity of WikiLeaks documents, the feasibility of rigorously proving software correctness, and the fact that nearly half a million people need to get their bodies' firmware updated. Another controversial CIA project is exposed by WikiLeaks. A careful analysis is done of the FCC's Title II Net Neutrality public comments. We talk about a neat two-factor auth tracking site, the Stupid Patent of the Month, an example of a vanity top-level domain, a bit of errata, and finish up with the utterly unconscionable security mistakes made by AT&T in their line of U-Verse routers.

56 MB

14 MB

359 KB

143 KB

95 KB

172 KB

Episode #626 | 29 Aug 2017 | 120 min.

Shattering TrustThis week we cover a bit of the ongoing drama surrounding Marcus Hutchins, examine a reported instance of interagency hacking, follow the evolving market for 0-day exploits, examine trouble arising from the continued use of a deprecated Apple security API, discover that Intel's controversial platform management engine CAN, after all be disabled, look into another SMS attack, bring note to a nice looking TOTP authenticator, recommend an alternative to the shutting-down CrashPlan, deal with a bit of errata and miscellany, then we look into an interesting bit of research which invokes "The Wrath of Kahn".

58 MB

14 MB

327 KB

136 KB

93 KB

167 KB

Episode #625 | 22 Aug 2017 | 129 min.

Security PoliticsThis week we discuss the continuing Marcus Hutchins drama, the disclosure of a potentially important Apple secret, a super-cool website and browser extension our listeners are going to appreciate, trouble with extension developers being targeted, a problem with the communication bus standard in every car, an important correction from Elcomsoft, two 0-days in Foxit's PDF products, Lavalamps for entropy, the forthcoming iOS 11 TouchID killswitch, very welcome Libsodium audit results, a mistake in AWS permissions, a refreshingly forthright security statement, a bit of errata, miscellany, and a few closing the loop bits from our terrific listeners!

61 MB

15 MB

475 KB

156 KB

99 KB

180 KB

Episode #624 | 15 Aug 2017 | 123 min.

Twelve and CountingThis week we have a Marcus Hutchins update, the backstory on the NIST's rewrite of their 15 year old password guidance, can DNA be used to hack a computer?, can stop sign graffiti be used to misdirect autonomous vehicles?, the final nail in the WoSign/StartCom coffin, why we need global Internet policy treaties, this week in "researchers need protection", a VPN provider who is doing everything right, Elcomsoft's password manager cracker, a bit of errata and miscellany... and some closing the loop feedback from this podcast's terrific listeners.

58 MB

15 MB

219 KB

121 KB

89 KB

157 KB

Episode #623 | 08 Aug 2017 | 125 min.

Inching ForwardThis week we discuss and look into DigiCert's acquisition of Symantec's certificate authority business unit, LogMeIn's LastPass Premium price hike, the troubling case of Marcus Hutchins' post-Defcon arrest, another instance of WannaCry-style SMBv1 propagation, this week's horrific IoT example, some hopeful IoT legislation, the consequences of rooting early Amazon Echoes, the drip drip drip of Wikileaks Vault 7 drips again, Mozilla's VERY interesting easy-to-use secure large file encrypted store and forward service, the need to know what your VPN service is really up to, a bit of errata, miscellany, and some closing-the-loop feedback from our always-attentive terrific listeners.

59 MB

15 MB

219 KB

139 KB

91 KB

163 KB

Episode #622 | 01 Aug 2017 | 102 min.

Hack the VoteThis week we look at the expected DEF CON fallout including the hacking of U.S. election voting machines, Microsoft’s enhanced Bug Bounty Program, the wormification of the Broadcom WiFi firmware flaw, the worries when autonomous AI agents begin speaking in their own language which we cannot understand, Apple’s pulling VPN clients from its Chinese App Store, a follow-up on iRobot’s floor plan mapping intentions, some news on the Chrome browser front, the 18th Vault 7 WikiLeaks dump, and some closing-the-loop feedback from our terrific podcast followers.

48 MB

12 MB

177 KB

119 KB

76 KB

144 KB

Episode #621 | 25 Jul 2017 | 123 min.

Crypto TensionWe start off this week with a fabulous Picture of the Week and, for the first time in this podcast’s 12-year history, our first Quote of the Week. Then we’ll be discussing the chilling effects of arresting ethical hackers, the upcoming neutrality debate congressional hearing, something troubling I encountered at McAfee.com, an entirely new IoT nightmare you couldn’t have seen coming and just won’t believe, the long-awaited Adobe Flash end-of-life schedule, welcome performance news for Firefox users, the FCC allocates new sensor spectrum for self-driving cars, three bits of follow-up errata, a bit of miscellany, and then Crypto Tension – a careful look at the presently ongoing controversy surrounding the deliberate provisioning of passive eavesdropping decryption being seriously considered for inclusion in the forthcoming TLS v1.3 standard.

59 MB

15 MB

263 KB

166 KB

98 KB

179 KB

Episode #620 | 18 Jul 2017 | 104 min.

Calm Before the StormThis week, while waiting for news from the upcoming BlackHat & DefCon conventions, we discuss another terrific security eBook bundle offer, a Net Neutrality follow-up, a MySpace account recovery surprise, another new feature coming to Win10, the wrong-headedness of paste-blocking web forms, Australia versus the laws of math, does an implanted pacemaker meet the self-incrimination exemption?, an updated worse-case crypto-future model, it's surprising what you can find at a flea market, another example of the consumer as the product, a SQRL technology update, and some closing-the-loop feedback from our terrific listeners.

49 MB

12 MB

250 KB

119 KB

80 KB

149 KB

Episode #619 | 11 Jul 2017 | 113 min.

All the Usual SuspectsThis week we have all the usual suspects: governments regulating their citizenry, evolving Internet standards, some brilliant new attack mitigations and some new side-channel attacks, browsers responding to negligent certificate authorities, specious tracking lawsuits, flying device jailbreaking, more IoT tomfoolery, this week’s horrifying Android vulnerability, more Vault 7 CIA WikiLeaks, a great tip about controlling the Internet through DNS – and even more! In other words, all of the usual suspects! (And two weeks until our annual Black Hat exploit extravaganza!)

When Governments ReactThis week we discuss France, Britain, Japan, Germany & Russia each veering around in their Crypto Crash Cars, Wikileaks' Vault7 reveals widespread CIA WiFi router penetration, why we can no longer travel with laptops, HP printer security insanity, how long are typical passwords?, Microsoft to kill off SMBv1, the all-time mega ransomware pay out, Google to get into the whole-system backup business, hacking PCs with "Vape Pens", a bit of miscellany, and a bunch of Closing the Loop feedback with our terrific listeners.

54 MB

14 MB

365 KB

153 KB

88 KB

165 KB

Episode #616 | 13 Jun 2017 | 124 min.

Things Are Getting WorseThis week we discuss clever malware hiding its social media communications. The NSA documents the Russian election hacking two-factor authentication bypass; meanwhile, other Russian attackers leverage Google’s own infrastructure to hide their spoofing. Tavis finds more problems in Microsoft’s anti-malware protection; a cryptocurrency stealing malware; more concerns over widespread Internet-connected camera design; malware found to be exploiting Intel’s AMT motherboard features; the new danger of mouse-cursor hovering; Apple’s iCloud sync security claims; Azure changes their CA; a bunch of catch-up miscellany; and a bit of “closing the loop” feedback from our listeners.

60 MB

15 MB

484 KB

125 KB

97 KB

169 KB

Episode #615 | 06 Jun 2017 | 119 min.

Legacy’s Long TailThis week we discuss an embarrassing high-profile breach of an online identity company, an overhyped problem found in Linux’s sudo command, the frightening software used by the U.K.’s Trident nuclear missile submarine launch platforms, how emerging nations prevent high school test cheating, another lesson about the danger of SMS authentication codes, another worrisome Shodan search result, high-penetration dangerous adware from a Chinese marketer, another “that’s not a bug” bug in Chrome allowing websites to surreptitiously record audio and video without the user’s knowledge, the foreseeable evolution of hybrid cryptomalware, the limp return of Google Contributor, Google continues to work on end-to-end email encryption, a follow-up on straight-to-voicemail policy, “homomorphic encryption” (what the heck is that?), and “closing the loop” follow-up from recent discussions.

57 MB

14 MB

251 KB

115 KB

93 KB

161 KB

Episode #614 | 30 May 2017 | 123 min.

Vulnerabilities Galore!This week we discuss a new non-email medium for spearphishing, Chipotle can’t catch a break, social engineering WannaCry exploits on Android, video subtitling now able to takeover our machines, a serious Android UI design flaw that Google appears to be stubbornly refusing to address, Linux gets its own version of WannaCry, another dangerous NSA exploit remains unpatched and publicly exploitable on WinXP and Server 2003 machines, a look at 1Password’s brilliant and perfect new Travel Mode, Google extends its ad tracking into the offline world, some follow-ups, miscellany, and closing-the-loop feedback from our terrific listeners – concluding with my possibly useful analogy to explain the somewhat confusing value of open versus closed source.

58 MB

15 MB

212 KB

137 KB

93 KB

168 KB

Episode #613 | 23 May 2017 | 129 min.

WannaCry AftermathThis week we examine a bunch of WannaCry follow-ups, including some new background, reports of abilities to decrypt drives, attacks on the kill switch, and more. We also look at what the large Stack Overflow site had to do to do HTTPS, the WiFi security of various properties owned by the U.S. President, more worrisome news coming from the U.K.'s Theresa May, the still sorry state of certificate revocation, are SSDs also subject to Rowhammer-like attacks, some miscellany, and closing the loop with our listeners.

62 MB

16 MB

453 KB

128 KB

92 KB

159 KB

Episode #612 | 16 May 2017 | 116 min.

Makes You WannaCryThis week Steve and Leo discuss an update on the FCC's Net Neutrality comments, the discovery of an active keystroke logger on dozens of HP computer models, the continuing loss of web browser platform heterogeneity, the OSTIF's just-completed OpenVPN security and practices audit, more on the dangers of using smartphones as authentication tokens, some extremely welcome news on the Android security front, long-awaited updated password recommendations from NIST, some follow-up errata, a bit of tech humor and miscellany, closing the loop with some listener feedback, and then a look at last week's global explosion of the WannaCry worm.

Intel's Mismanagement EngineThis week Steve and Leo discuss the long-expected remote vulnerability in Intel's super-secret motherboard Management Engine technology, exploitable open ports in Android apps, another IoT blows a suspect's timeline, newly discovered problems in the Ghostscript interpreter, yet another way for ISPs and others to see where we go, a new bad problem in the Edge browser, Chrome changes its certificate policy, an interesting new "vigilante botnet" is growing fast, a proposed solution to smartphone-distracted driving, ransomware as a service, Net Neutrality heads back to the chopping block (again), an intriguing new service from Cloudflare, and the ongoing Symantec certificate issuance controversy. Then some fun errata, miscellany, and some "closing the loop" feedback from our terrific listeners.

66 MB

16 MB

208 KB

147 KB

100 KB

173 KB

Episode #609 | 25 Apr 2017 | 107 min.

The Double PulsarThis week Steve and Leo discuss how one of the NSA's Vault7 vulnerabilities has gotten loose, a clever hacker removes Microsoft deliberate (and apparently unnecessary) block on Win7/8.1 updates for newer processors, Microsoft refactors multifactor authentication, Google to add native ad-blocking to Chrome… and what exactly *are* abusive ads?, Mastercard to build a questionable fingerprint sensor into their cards, are Bose headphones spying on their listeners?, 10 worrisome security holes discovered in Linksys routers, MIT cashes out half of its IPv4 space, and the return of two meaner BrickerBots. Then some Errata, a bit of Miscellany, and, time permitting, some "Closing the Loop" feedback from our podcast's terrific listeners.

51 MB

13 MB

270 KB

129 KB

82 KB

151 KB

Episode #608 | 18 Apr 2017 | 127 min.

News & Feedback PotpourriThis week Steve and Leo discuss another new side-channel attack on smartphone PIN entry (and much more), Smartphone fingerprint readers turn out to be far more spoofable that we had hoped. All Linux kernels prior to v4.5 are vulnerable to a serious remote network attack over UDP, a way to prevent Google from tracking the search links we click (and to allow us to copy the links from the search results), the latest NSA Vault7 data dump nightmare, the problem with punycode domains, four years after the public UPnP router exposure, looking closely at the mixed blessing of hiding WiFi access point SSID broadcasts, some miscellany, and then a collection of quick "Closing The Loop" follow-ups from last week's "Proactive Privacy" podcast.

61 MB

15 MB

265 KB

122 KB

90 KB

155 KB

Episode #607 | 11 Apr 2017 | 139 min.

Proactive Privacy (Really, this time!)This week Steve and Leo discuss Symantec finding 40 past attacks explained by the Vault 7 document leaks, an incremental improvement coming to CA certificate issuance, and Microsoft’s patching of a zero-day Office vulnerability that was being exploited in the wild. They ask, “What’s a Brickerbot?” They cover why you need a secure DNS registrar, This Week in IoT Tantrums, a headshaker from our “You really can’t make this stuff up” department, the present danger of fake VPN services, and an older edition of Windows reaching end of patch life. They continue with some “closing the loop” feedback from their listeners and a bit of miscellany, then close with a comprehensive survey of privacy-encroaching technologies and what can be done to limit their grasp.

67 MB

17 MB

225 KB

150 KB

102 KB

178 KB

Episode #606 | 04 Apr 2017 | 115 min.

Proactive PrivacyThis week Steve and Leo discuss another iOS update update, more bad news and some good news on the IoT front, the readout on Tavis Ormandy's shower revelation, more worrisome anti-encryption saber rattling from the EU, a look at a recent Edward Snowden tweet, Samsung's S8 mistake, an questionable approach to online privacy, celebrating the 40th anniversary of Alice and Bob, some quickie feedback loops from our listeners, an update on my projects, and a
comprehensive examination of proactive steps users can take to enhance their online privacy.

54 MB

14 MB

210 KB

148 KB

87 KB

160 KB

Episode #605 | 28 Mar 2017 | 142 min.

Google -vs- SymantecThis week Jason and I discuss Google’s Tavis Ormandy taking an inspiration shower, iOS gets a massive feature and security update, a new target for ‘Bot money harvesting appears, Microsoft suffers a rather significant user-privacy fail, the UK increases its communications decryption
rhetoric, a worrisome vote in the US senate, NEST fails to respond to a researcher's report, this week in IoT nonsense, a fun quote of the week, a bit of miscellany, some quickie questions from our listeners, and a close look at the developing drama surrounding Google's enforcement of the Certificate Authority Baseline rules with Symantec.

68 MB

17 MB

416 KB

123 KB

106 KB

175 KB

Episode #604 | 21 Mar 2017 | 117 min.

Taming Web AdsThis week Leo and I discuss developments in the New Windows on Old Hardware front, Cisco finds a surprise in the Vault 7 docs, Ubiquiti was caught with their PHPs down, Check Point discovered problems in WhatsApp and Telegram, some interesting details about the long-running Yahoo breaches, the death of the “eBay Football,” the latest amazing IoT insanity, the incredible results of the CanSecWest Pwn2Own competition, a classic “you’re doing it wrong” example, Tavis pokes LastPass again, some miscellany, and an interesting proposal about controlling web advertising abuse.

56 MB

14 MB

248 KB

126 KB

85 KB

153 KB

Episode #603 | 14 Mar 2017 | 108 min.

Vault 7This week Leo and I discuss March's long-awaited patch Tuesday, the release deployment of Google Invisible reCaptcha, getting more than you bargained for with a new Android smartphone, the new "Find my iPhone" phishing campaign, the failure of WiFi anti-tracking, a nasty and significant new hard-to-fix web server 0-day vulnerability, what if your ISP decides to unilaterally block a service you depend upon?, shining some much-needed light onto a poorly conceived end-to-end messaging application, two quick takes, a bit of errata and miscellany... and a look into what Wikileaks revealed about the CIA's data collection capabilities and practices.

51 MB

13 MB

176 KB

131 KB

83 KB

153 KB

Episode #602 | 07 Mar 2017 | 138 min.

Let's SpoofThis week, Leo and I discuss the countdown to March’s Patch Tuesday. What was behind Amazon’s S3 outage? Why don’t I have a cellular connectivity backup? We share some additional Cloudflare perspective. Amazon will fight another day over their Voice Assistant’s privacy. An examination of the top nine Android password managers uncovers problems. We’ll cover another fileless malware campaign found in the wild; security improvements in Chrome and Firefox; a proof of concept for BIOS ransomware; a how-to walk-through for return-oriented programming; a nifty new site-scanning service.

66 MB

17 MB

360 KB

140 KB

103 KB

177 KB

Episode #601 | 28 Feb 2017 | 101 min.

The First SHA-1 CollisionThis week, Leo and I discuss the “CloudBleed” incident; another project zero 90-day timer expires for Microsoft; this week's IoT head-shaker; a New York airport exposes critical server data for a year; another danger created by inline third party TLS-intercepting "middleboxes"; more judicial thrashing over fingerprint warrants; Amazon says no to Echo data warrant; a fun drone-enabled proof on concept is widely misunderstood; another example of A/V attack surface expansion; some additional Crypto education pointers and miscellany... and, finally, what does Google's deliberate creation of two SHA-1-colliding files actually mean?

48 MB

12 MB

220 KB

133 KB

80 KB

148 KB

Episode #600 | 21 Feb 2017 | 124 min.

The MMU Side-Channel AttackThis week, Leo and I discuss the completely cancelled February patch Tuesday amid a flurry of serious problems; it's not only laptop webcams that we need to worry about; the perils of purchasing a previously-owned Internet connected auto; Chrome changes its UI making certificate inspection trickier; the future of Firefox Add-Ons; Win10's lock screen is leaking the system’s clipboard; a collection of new problems for Windows; a amazing free Crypto book online from Stanford and New York University; pfSense and Ubiquity follows-ups; a bit of geek humor and miscellany… And a deep dive into yet another sublime hack from our ever-clever friends, led by professor Herbert Bos at the University of Amsterdam.

59 MB

15 MB

206 KB

127 KB

89 KB

155 KB

Episode #599 | 14 Feb 2017 | 102 min.

TLS Interception INsecurityThis week, Leo and I discuss the delay in this month's Patch Tuesday (we may know why!), our favorite ad-blocker embraces the last major browser, a university gets attacked by its own vending machines, PHP leaps into the future, a slick high-end Linux hack, the rise of fileless malware, some good advice for tax time, it's not only Android's pattern lock that's vulnerable to visual eavesdropping, what happens with you store a huge pile of Samsung Note 7's in one place?, some fun miscellany, a MUST NOT MISS science fiction TV series, a look at the growing worrisome security implications of uncontrolled TLS interception.

48 MB

12 MB

260 KB

110 KB

72 KB

133 KB

Episode #598 | 07 Feb 2017 | 115 min.

Two Armed BanditsThis week, Leo and I discuss printers around the world getting hacked!, Vizio's TVs really were watching their watchers, Windows has a new 0-day problem, Android's easy-to-hack pattern lock, an arsonist's pacemaker rats him out, a survey finds that many iOS apps are not checking TLS certificates, the courts create continuing confusion over eMail search warrants, a blast from the past: SQL Slammer appears to return, Cellebrite's stolen cell phone cracking data begins to surface, some worrisome events in the Encrypted Web Extensions debate, Non-Windows 10 users are not alone, a couple of questions answered, my report of a terrific Sci-Fi series, a bit of other miscellany... and a fun story about one armed bandits being hacked by two armed bandits..

54 MB

14 MB

257 KB

116 KB

85 KB

150 KB

Episode #597 | 31 Jan 2017 | 107 min.

Traitors in our MidstThis week, Leo and I discuss the best “I'm not a Robot” video ever; Cisco's WebEx problem being far more pervasive than first believed; More bad news (and maybe some good news) for Netgear; Gmail adds .js to the no-no list; a hotel finally decides to abandon electronic room keying; more arguments against the use of modern AV; another clever exploitable CSS browser hack; some (hopefully final) password complexity follow-ups; a bit of errata and miscellany; a SQRL status update; a “Luke... trust the SpinRite” story; and a very nice analysis of a little-suspected threat hiding among us.

51 MB

13 MB

322 KB

115 KB

80 KB

143 KB

Episode #596 | 24 Jan 2017 | 119 min.

Password Complexity CalculationsThis week, Leo and I discuss how, while still on probation Symantec issues additional invalid certificates, Tavis Ormandy finds a very troubling problem in Cisco's Web conferencing extension for Chrome, yesterday's more-important-than-usual update to iOS, renewed concerns about LastPass metadata leakage, the SEC looks askance at what's left of Yahoo, a troubling browser form auto-fill information leakage, Tor further hides its hidden services, China orbits a source of entangles photons?, Heartbleed three years later, a new take on compelling fingerprints, approaching the biggest Pwn2Own ever, some miscellany... and some tricks for computing password digit and bit complexity equivalence.

56 MB

14 MB

207 KB

112 KB

84 KB

146 KB

Episode #595 | 17 Jan 2017 | 113 min.

Whats up with WhatsApp?This week, Leo and I discuss a classic bug at GoDaddy which bypassed domain validation for 8850 issued certificates; could flashing a peace sign compromise your biometric data?; it's not only new IoT devices that may tattle on you: many autos have been able to for the past 15 years; McDonalds gets caught in a web security bypass; more famous hackers have been hacked; Google uses AI to increase image resolution; more on the value or danger of password tricks; and... does WhatsApp incorporate a deliberate crypto backdoor?

54 MB

14 MB

234 KB

120 KB

85 KB

150 KB

Episode #594 | 10 Jan 2017 | 112 min.

A look into PHP malwareThis week, Leo and I discuss the US Federal Trade Commission's step into the IoT and home networking malpractice world, a radio station learning a lesson about what words NOT to repeat, Google's plan to even eliminate the "checkbox", a crucial caveat to the "passwords are long enough" argument, more cause to be wary of third-party software downloads, a few follow-ups to last week's topics, a bit of miscellany and a close look at the government's Russian hacking disclosure and a well-known piece of (related?) PHP malware.

53 MB

13 MB

224 KB

126 KB

86 KB

152 KB

Episode #593 | 03 Jan 2017 | 107 min.

I'm NOT a Robot! (Really)This week, Leo and I discuss law enforcement and the Internet of Tattling things, a very worrisome new and widespread PHP eMail vulnerability, Paul and MaryJo score a big concession from Microsoft, a six year old "hacker" makes the news, Apple discovers how difficult it is to make developers change, hyperventilation over Russian malware found on a power utility's laptop, the required length of high entropy passwords, more pain for Netgear, an update on the just finalized v1.3 of TLS, the EFF's growing "Secure" messaging scorecard, a bunch of fun miscellany... and how does that "I'm not a Robot" non-CAPTCHA checkbox CAPTCHA work?

You can receive an eMail reminder whenever this page is updated with a new Security Now! episode. Click the "Monitor Changes" button to have the highly-regarded "Change Detection" web site monitor this page and send you a note when it changes.